| URL: | https://disk.yandex.ru/d/-_JloFilTbD_lg |
| Full analysis: | https://app.any.run/tasks/1c1906ca-2886-4612-a299-5a099c53f927 |
| Verdict: | Malicious activity |
| Threats: | RedLine Stealer is a malicious program that collects users’ confidential data from browsers, systems, and installed software. It also infects operating systems with other malware. |
| Analysis date: | November 11, 2023, 12:49:17 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 64 bit) |
| Tags: | |
| Indicators: | |
| SHA1: | 9A43B43D84CF8DFE9899B5E802C5F72C9BE3801F |
| SHA256: | 3F657B4EACE136FD2E1C5B14D4BB190F7789D9187B1C2FA929D8B3477EEFB9A0 |
| SSDEEP: | 3:N8U2ExR:2U2EP |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 992 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="2700.0.1155360764\2135018522" -parentBuildID 20230710165010 -prefsHandle 1096 -prefMapHandle 1088 -prefsLen 29780 -prefMapSize 244187 -appDir "C:\Program Files\Mozilla Firefox\browser" - {60058901-ae32-4bb2-bf2d-1e03d8f81984} 2700 "\\.\pipe\gecko-crash-server-pipe.2700" 1168 46ced58 gpu | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Firefox Exit code: 0 Version: 115.0.2 Modules
| |||||||||||||||
| 1968 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="2700.3.1325148628\1921437084" -childID 2 -isForBrowser -prefsHandle 2888 -prefMapHandle 2876 -prefsLen 35402 -prefMapSize 244187 -jsInitHandle 868 -jsInitLen 240908 -parentBuildID 20230710165010 -appDir "C:\Program Files\Mozilla Firefox\browser" - {c5cfb8e4-d857-4ffd-923b-b27851c4820c} 2700 "\\.\pipe\gecko-crash-server-pipe.2700" 2900 1e5e8b58 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Firefox Exit code: 0 Version: 115.0.2 Modules
| |||||||||||||||
| 2008 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="2700.4.1231540608\1418974869" -childID 3 -isForBrowser -prefsHandle 3736 -prefMapHandle 3520 -prefsLen 30253 -prefMapSize 244187 -jsInitHandle 868 -jsInitLen 240908 -parentBuildID 20230710165010 -appDir "C:\Program Files\Mozilla Firefox\browser" - {4a8c9487-1c8f-4c34-86ac-197d8558693a} 2700 "\\.\pipe\gecko-crash-server-pipe.2700" 3748 22d81c58 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Firefox Exit code: 0 Version: 115.0.2 Modules
| |||||||||||||||
| 2576 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="2700.1.419357371\59285992" -parentBuildID 20230710165010 -prefsHandle 1396 -prefMapHandle 1392 -prefsLen 29857 -prefMapSize 244187 -appDir "C:\Program Files\Mozilla Firefox\browser" - {ec5da1a4-b872-44a6-8d1a-1e79f0e1b04c} 2700 "\\.\pipe\gecko-crash-server-pipe.2700" 1408 46d0e58 socket | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Firefox Exit code: 0 Version: 115.0.2 Modules
| |||||||||||||||
| 2700 | "C:\Program Files\Mozilla Firefox\firefox.exe" "https://disk.yandex.ru/d/-_JloFilTbD_lg" | C:\Program Files\Mozilla Firefox\firefox.exe | explorer.exe | ||||||||||||
User: admin Company: Mozilla Corporation Integrity Level: MEDIUM Description: Firefox Exit code: 0 Version: 115.0.2 Modules
| |||||||||||||||
| 2744 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="2700.6.2073949481\1530908621" -childID 5 -isForBrowser -prefsHandle 4036 -prefMapHandle 4040 -prefsLen 30253 -prefMapSize 244187 -jsInitHandle 868 -jsInitLen 240908 -parentBuildID 20230710165010 -appDir "C:\Program Files\Mozilla Firefox\browser" - {136e14a7-d3eb-4eef-8b34-009cb7f744d1} 2700 "\\.\pipe\gecko-crash-server-pipe.2700" 4024 2340bd58 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Firefox Exit code: 0 Version: 115.0.2 Modules
| |||||||||||||||
| 2780 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="2700.7.1817072050\1652459415" -childID 6 -isForBrowser -prefsHandle 4780 -prefMapHandle 4500 -prefsLen 35561 -prefMapSize 244187 -jsInitHandle 868 -jsInitLen 240908 -parentBuildID 20230710165010 -appDir "C:\Program Files\Mozilla Firefox\browser" - {006634c9-ea05-4db8-982f-85137bca6f12} 2700 "\\.\pipe\gecko-crash-server-pipe.2700" 5908 e7b658 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Firefox Exit code: 0 Version: 115.0.2 Modules
| |||||||||||||||
| 2812 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="2700.5.1770837845\1570005536" -childID 4 -isForBrowser -prefsHandle 3768 -prefMapHandle 3756 -prefsLen 30253 -prefMapSize 244187 -jsInitHandle 868 -jsInitLen 240908 -parentBuildID 20230710165010 -appDir "C:\Program Files\Mozilla Firefox\browser" - {f41f2418-8843-4010-a3c6-3d398ec244cb} 2700 "\\.\pipe\gecko-crash-server-pipe.2700" 3780 1e3bb558 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Firefox Exit code: 0 Version: 115.0.2 Modules
| |||||||||||||||
| 2948 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="2700.2.965310401\2110894171" -childID 1 -isForBrowser -prefsHandle 2012 -prefMapHandle 2008 -prefsLen 25589 -prefMapSize 244187 -jsInitHandle 868 -jsInitLen 240908 -parentBuildID 20230710165010 -appDir "C:\Program Files\Mozilla Firefox\browser" - {440b3bfa-491a-4093-ac51-5ea27a0ccd62} 2700 "\\.\pipe\gecko-crash-server-pipe.2700" 2024 1974a558 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Firefox Exit code: 0 Version: 115.0.2 Modules
| |||||||||||||||
| 3356 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="2700.8.1870933902\321844587" -childID 7 -isForBrowser -prefsHandle 6752 -prefMapHandle 8240 -prefsLen 30425 -prefMapSize 244187 -jsInitHandle 868 -jsInitLen 240908 -parentBuildID 20230710165010 -appDir "C:\Program Files\Mozilla Firefox\browser" - {e4f5e789-32ab-4147-8a2e-df7c0b154060} 2700 "\\.\pipe\gecko-crash-server-pipe.2700" 8232 26eee858 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Firefox Exit code: 0 Version: 115.0.2 Modules
| |||||||||||||||
| (PID) Process: | (2700) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Mozilla\Firefox\Launcher |
| Operation: | write | Name: | C:\Program Files\Mozilla Firefox\firefox.exe|Browser |
Value: 0000000000000000 | |||
| (PID) Process: | (2700) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Mozilla\Firefox\Launcher |
| Operation: | write | Name: | C:\Program Files\Mozilla Firefox\firefox.exe|Telemetry |
Value: 1 | |||
| (PID) Process: | (2700) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Mozilla\Firefox\DllPrefetchExperiment |
| Operation: | write | Name: | C:\Program Files\Mozilla Firefox\firefox.exe |
Value: 0 | |||
| (PID) Process: | (2700) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Mozilla\Firefox\PreXULSkeletonUISettings |
| Operation: | write | Name: | C:\Program Files\Mozilla Firefox\firefox.exe|Theme |
Value: 1 | |||
| (PID) Process: | (2700) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Mozilla\Firefox\PreXULSkeletonUISettings |
| Operation: | write | Name: | C:\Program Files\Mozilla Firefox\firefox.exe|Enabled |
Value: 1 | |||
| (PID) Process: | (2700) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Mozilla\Firefox\Default Browser Agent |
| Operation: | write | Name: | C:\Program Files\Mozilla Firefox|DisableTelemetry |
Value: 0 | |||
| (PID) Process: | (2700) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Mozilla\Firefox\Default Browser Agent |
| Operation: | write | Name: | C:\Program Files\Mozilla Firefox|DisableDefaultBrowserAgent |
Value: 0 | |||
| (PID) Process: | (2700) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Mozilla\Firefox\Default Browser Agent |
| Operation: | write | Name: | C:\Program Files\Mozilla Firefox|SetDefaultBrowserUserChoice |
Value: 1 | |||
| (PID) Process: | (2700) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Mozilla\Firefox\Default Browser Agent |
| Operation: | write | Name: | C:\Program Files\Mozilla Firefox|AppLastRunTime |
Value: F8B731ACA1C5D901 | |||
| (PID) Process: | (2700) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings |
| Operation: | write | Name: | ProxyEnable |
Value: 0 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 2700 | firefox.exe | C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\nltxvmn2.default\startupCache\urlCache-current.bin | binary | |
MD5:4DF9B77C7650AF87B264E535779AE2A4 | SHA256:C57071FCFEF26EE4F08A2029E547848EC015B10045ABAD705195A9F966FEAE58 | |||
| 2700 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\nltxvmn2.default\sessionCheckpoints.json | binary | |
MD5:EA8B62857DFDBD3D0BE7D7E4A954EC9A | SHA256:792955295AE9C382986222C6731C5870BD0E921E7F7E34CC4615F5CD67F225DA | |||
| 2700 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\nltxvmn2.default\prefs.js | text | |
MD5:5B83C501F85021C15F12D79183C9471C | SHA256:023CD5099D78F9D71781555D7565573F80D25138D2FEC93012381CAD6FCB95E8 | |||
| 2700 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\nltxvmn2.default\sessionCheckpoints.json.tmp | binary | |
MD5:EA8B62857DFDBD3D0BE7D7E4A954EC9A | SHA256:792955295AE9C382986222C6731C5870BD0E921E7F7E34CC4615F5CD67F225DA | |||
| 2700 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\nltxvmn2.default\prefs-1.js | text | |
MD5:5B83C501F85021C15F12D79183C9471C | SHA256:023CD5099D78F9D71781555D7565573F80D25138D2FEC93012381CAD6FCB95E8 | |||
| 2700 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\nltxvmn2.default\cert9.db-journal | binary | |
MD5:247D2082C753EA422B03F7D00F38E247 | SHA256:4BE0DD27AAFA9018B5D79725F42419EA940AA4E672578D552612B460211CE4F3 | |||
| 2700 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\nltxvmn2.default\storage\permanent\chrome\idb\3870112724rsegmnoittet-es.sqlite-shm | binary | |
MD5:B7C14EC6110FA820CA6B65F5AEC85911 | SHA256:FD4C9FDA9CD3F9AE7C962B0DDF37232294D55580E1AA165AA06129B8549389EB | |||
| 2700 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\nltxvmn2.default\storage\permanent\chrome\idb\1657114595AmcateirvtiSty.sqlite-shm | binary | |
MD5:B7C14EC6110FA820CA6B65F5AEC85911 | SHA256:FD4C9FDA9CD3F9AE7C962B0DDF37232294D55580E1AA165AA06129B8549389EB | |||
| 2700 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\nltxvmn2.default\datareporting\glean\db\data.safe.tmp | binary | |
MD5:323E80CC403D4E0E9D3850F7431B9A02 | SHA256:88CBAE17EE862AAD117EFD3F3D500F0B7A17B042CC71244E36F04047943E832B | |||
| 2700 | firefox.exe | C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\nltxvmn2.default\cache2\entries\ED9826654AE8BD972BDE17A9E0A449D3F881E430 | binary | |
MD5:1F62311764DD24095B813C290C5C602F | SHA256:E308682E792B2DB86FA9339470932E5729207DDF755FCF34016847FA0A9FD702 | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
2700 | firefox.exe | GET | 200 | 34.107.221.82:80 | http://detectportal.firefox.com/success.txt?ipv4 | unknown | text | 8 b | unknown |
2700 | firefox.exe | POST | 200 | 23.53.40.161:80 | http://r3.o.lencr.org/ | unknown | binary | 503 b | unknown |
2700 | firefox.exe | POST | 200 | 104.18.20.226:80 | http://ocsp.globalsign.com/gsrsaovsslca2018 | unknown | binary | 1.40 Kb | unknown |
2700 | firefox.exe | GET | 200 | 34.107.221.82:80 | http://detectportal.firefox.com/canonical.html | unknown | text | 90 b | unknown |
2700 | firefox.exe | POST | 200 | 104.18.20.226:80 | http://ocsp.globalsign.com/gsrsaovsslca2018 | unknown | binary | 1.40 Kb | unknown |
2700 | firefox.exe | POST | 200 | 142.250.185.163:80 | http://ocsp.pki.goog/gts1c3 | unknown | binary | 472 b | unknown |
2700 | firefox.exe | POST | 200 | 23.53.40.161:80 | http://r3.o.lencr.org/ | unknown | binary | 503 b | unknown |
2700 | firefox.exe | POST | 200 | 23.53.40.161:80 | http://r3.o.lencr.org/ | unknown | binary | 503 b | unknown |
2700 | firefox.exe | POST | 200 | 142.250.185.163:80 | http://ocsp.pki.goog/gts1c3 | unknown | binary | 472 b | unknown |
2700 | firefox.exe | POST | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/ | unknown | binary | 471 b | unknown |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
2700 | firefox.exe | 87.250.250.50:443 | disk.yandex.ru | YANDEX LLC | RU | whitelisted |
324 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
2700 | firefox.exe | 34.107.221.82:80 | detectportal.firefox.com | GOOGLE | US | whitelisted |
2700 | firefox.exe | 34.117.237.239:443 | contile.services.mozilla.com | GOOGLE-CLOUD-PLATFORM | US | unknown |
2700 | firefox.exe | 107.21.198.143:443 | spocs.getpocket.com | AMAZON-AES | US | unknown |
2700 | firefox.exe | 104.18.20.226:80 | ocsp.globalsign.com | CLOUDFLARENET | — | shared |
2700 | firefox.exe | 23.53.40.161:80 | r3.o.lencr.org | Akamai International B.V. | DE | unknown |
2700 | firefox.exe | 34.160.144.191:443 | content-signature-2.cdn.mozilla.net | GOOGLE | US | unknown |
2700 | firefox.exe | 142.250.184.234:443 | safebrowsing.googleapis.com | — | — | whitelisted |
Domain | IP | Reputation |
|---|---|---|
detectportal.firefox.com |
| whitelisted |
disk.yandex.ru |
| shared |
prod.detectportal.prod.cloudops.mozgcp.net |
| whitelisted |
contile.services.mozilla.com |
| whitelisted |
example.org |
| whitelisted |
ipv4only.arpa |
| whitelisted |
spocs.getpocket.com |
| shared |
proxyserverecs-1736642167.us-east-1.elb.amazonaws.com |
| shared |
ocsp.globalsign.com |
| whitelisted |
r3.o.lencr.org |
| shared |
PID | Process | Class | Message |
|---|---|---|---|
3528 | Loader.exe | Potentially Bad Traffic | ET INFO Microsoft net.tcp Connection Initialization Activity |
3528 | Loader.exe | A Network Trojan was detected | ET MALWARE [ANY.RUN] RedLine Stealer Related (MC-NMF Authorization) |
3528 | Loader.exe | A Network Trojan was detected | ET MALWARE Redline Stealer TCP CnC Activity - MSValue (Outbound) |
3528 | Loader.exe | A Network Trojan was detected | ET MALWARE Redline Stealer TCP CnC Activity - MSValue (Outbound) |
3528 | Loader.exe | A Network Trojan was detected | ET MALWARE Redline Stealer Activity (Response) |
3528 | Loader.exe | Successful Credential Theft Detected | SUSPICIOUS [ANY.RUN] Clear Text Password Exfiltration Atempt |
3528 | Loader.exe | Successful Credential Theft Detected | SUSPICIOUS [ANY.RUN] Clear Text Password Exfiltration Atempt |